Medium1 markMultiple Choice
Area II: SecurityIncident ResponseArea II

CPA · Question 82 · Area II: Security

An auditor finds that a company's 'Incident Response Plan' has not been tested or updated in 3 years. What is the primary recommendation?

Answer options:

A.

Rewrite the plan immediately.

B.

Conduct a tabletop exercise to test the plan and update it based on lessons learned.

C.

Wait for a real incident to test the plan.

D.

Purchase cyber insurance.

How to approach this question

Identify the best practice for maintaining plans.

Full Answer

B.Conduct a tabletop exercise to test the plan and update it based on lessons learned.✓ Correct
A tabletop exercise is a discussion-based session where team members meet in an informal, classroom setting to discuss their roles during an emergency and their responses to a particular situation.

Common mistakes

None usually.

Practice the full CPA ISC Practice Exam 2

82 questions · hints · full answers · grading

More questions from this exam